Understand the evidence behind ECC readiness.
This educational page helps teams discuss selected Essential Cybersecurity Controls and identify evidence gaps. It is not a complete legal interpretation, certification, or auditor assessment.
What Is ECC and Why It Matters
The Essential Cybersecurity Controls (ECC-1:2018) define a cybersecurity baseline published by the NCA for relevant organizations in Saudi Arabia. A gap may create regulatory and business risk, but applicability and compliance require qualified review.
A readiness review should connect each relevant control objective to current, reviewable evidence. SOCRoot can help structure that mapping, but it does not claim continuous measurement of every control or certify compliance.
All 5 ECC Domains Covered
Cybersecurity Governance
Policy frameworks, risk ownership, roles and accountability — the foundation everything else is built on.
Cybersecurity Defense
Endpoint protection, vulnerability management, network segmentation, and continuous external scanning.
Cybersecurity Resilience
Incident response plans, business continuity, disaster recovery, and backup integrity testing.
Third-Party Cybersecurity
Vendor risk assessments, contractual cybersecurity requirements, and securing supply chains.
Self-Assessment Checklist
Use this simplified checklist as a conversation starter. Its score is educational and must not be represented as an ECC compliance result.
Simplified Readiness Score
0%
0 / 16 controls
7 critical gapsStart checking items to explore which evidence may exist.
Educational self-assessment only. This score is not certification, legal advice, or an auditor opinion.
7 critical controls not implemented
Treat these selections as prompts for evidence review, not as confirmed control failures or a remediation estimate.
Prepare an Authorized ReviewA responsible readiness workflow
- 1
Initial Gap Analysis
Agree the applicable control objectives, scope, evidence sources, owners, and exclusions before rating readiness.
- 2
Remediation Roadmap
Record current evidence, missing evidence, uncertainty, and the operational impact of each gap.
- 3
Prioritized Improvement Work
Translate validated gaps into prioritized technical and governance work with accountable owners.
- 4
Evidence Package
Retest improvements and organize evidence for internal review or an independent qualified assessor.
Start with scope and evidence
A useful readiness conversation begins with applicable obligations, asset ownership, evidence sources, and the decision the review needs to support.